Data Processing Agreement

Last updated: August 30, 2026

This agreement applies whenever GTM Studio processes personal data on behalf of a client. It is part of the engagement contract and follows Article 28 GDPR. Plain language on purpose; the obligations are real.

1. Parties, scope, and roles

The client is the data controller. GTM Studio ([legal entity name], [address]) is the data processor. This DPA covers all personal data we touch while building and running the client's go-to-market system.

2. Details of the processing

Subject matter: market mapping, signal tracking, account scoring, and outreach operations. Duration: the engagement term. Data subjects: people in business roles at companies in the client's market. Data categories: name, role, company, work contact details, and public business signals. No special categories of data are processed.

3. Instructions

We process personal data only on the client's documented instructions — the engagement scope and written changes to it. If an instruction would break the law, we say so instead of following it.

4. Confidentiality

Everyone who works on an engagement is bound to confidentiality by contract. Access to client data is limited to the people who run that engagement.

5. Security measures

Encryption in transit, access on a need-to-use basis, two-factor authentication on all work accounts, and separation of each client's data in the client's own tool accounts. A detailed measure list is kept in the engagement annex.

6. Subprocessors

The client authorizes the subprocessors listed in the engagement annex (hosting, enrichment, outreach, and CRM tools agreed for the engagement). We announce changes in advance and the client can object on reasonable data protection grounds.

7. Data subject requests

Requests from data subjects go to the client. We help with the technical side — finding, correcting, exporting, or deleting the data — without undue delay.

8. Breach notification

If we learn of a personal data breach affecting client data, we notify the client without undue delay and share what we know so the client can meet its own deadlines.

9. Deletion and return

The system and its data belong to the client and live in the client's accounts. At the end of the engagement we hand over anything still in our hands and delete our copies, unless law requires retention.

10. Audits

We answer reasonable audit questions and provide the documentation needed to show compliance. On-site audits happen at most once a year, with notice, during business hours.

11. International transfers

Transfers outside the EEA rely on EU Standard Contractual Clauses or an adequacy decision, as listed per subprocessor in the annex.

12. Liability, precedence, and term

Liability follows the engagement contract. If this DPA conflicts with the contract, the DPA wins on data protection matters. The DPA runs as long as we process personal data for the client.